aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-client/src/preload.js
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 12:57:58 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 12:57:58 +0200
commit2c6921aa2c35ffd41b6c453e6700574ef631ba2c (patch)
tree01c766e13607e4f957900bfd36b4f722e8c8b3c5 /packages/meshbay-client/src/preload.js
parent8a4651e9d223de856ff085b329801998f95db138 (diff)
downloadmeshbay-2c6921aa2c35ffd41b6c453e6700574ef631ba2c.tar.gz
fix(client): the page names node operations, and the app confirms what widens the node
node:call is replaced by named operations with checked arguments; hosting a group, sharing an unpicked folder, key rotation, denylist clearing and a change of node account are confirmed by a native dialog. Every channel checks its sender, secrets:get/set/clear are gone, node:start writes the app's own hub. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-client/src/preload.js')
-rw-r--r--packages/meshbay-client/src/preload.js19
1 files changed, 12 insertions, 7 deletions
diff --git a/packages/meshbay-client/src/preload.js b/packages/meshbay-client/src/preload.js
index c2a2bd4..632718b 100644
--- a/packages/meshbay-client/src/preload.js
+++ b/packages/meshbay-client/src/preload.js
@@ -55,6 +55,11 @@ contextBridge.exposeInMainWorld('meshbay', {
// again after a language change.
setTrayLabels: (labels) => ipcRenderer.invoke('tray:labels', labels),
+ // The interface's language, so the confirmations the main process draws for
+ // itself are worded in it. A code, never text: the words are read from the
+ // packaged catalogues by the main process.
+ setLocale: (code) => ipcRenderer.invoke('ui:locale', code),
+
// Ask the main process to call the hub. The renderer has an `app://` origin,
// which CORS refuses and which is not a credential anyway.
fetch: (url, init) => ipcRenderer.invoke('hub:fetch', url, init),
@@ -75,10 +80,9 @@ contextBridge.exposeInMainWorld('meshbay', {
forget: () => ipcRenderer.invoke('device:forget'),
},
+ // Whether the OS protects what the main process stores. The store itself is
+ // not reachable from here: it holds the device key above.
secrets: {
- get: (name) => ipcRenderer.invoke('secrets:get', name),
- set: (name, value) => ipcRenderer.invoke('secrets:set', name, value),
- clear: (name) => ipcRenderer.invoke('secrets:clear', name),
// 'unprotected_fallback' means safeStorage found no keyring and is using a
// fixed key. Encrypted on disk, by a key that is not a secret — the
// interface says so rather than letting someone believe otherwise.
@@ -100,8 +104,9 @@ contextBridge.exposeInMainWorld('meshbay', {
},
// The local node, if one is running. The renderer never sees the session
- // token — it names an operation and the main process executes it, the same
- // pattern as hub:fetch.
+ // token, and never names a route: it names one of the operations the
+ // interface performs, the main process checks its arguments, builds the
+ // request and confirms natively what widens what the node shares.
node: {
detect: () => ipcRenderer.invoke('node:detect'),
installed: () => ipcRenderer.invoke('node:installed'),
@@ -110,13 +115,13 @@ contextBridge.exposeInMainWorld('meshbay', {
// PATH. Windows only; other platforms always resolve true.
bundled: () => ipcRenderer.invoke('node:bundled'),
start: (opts) => ipcRenderer.invoke('node:start', opts),
- call: (method, path, body) => ipcRenderer.invoke('node:call', method, path, body),
+ op: (name, args) => ipcRenderer.invoke('node:op', name, args),
pairingCode: () => ipcRenderer.invoke('node:pairing-code'),
setPairingCode: (code) => ipcRenderer.invoke('node:set-pairing-code', code),
// The daemon's lifecycle as seen from outside it: the systemd unit (Linux)
// or, on Windows, a probe of the daemon plus whether the Startup launcher
// is in place — reachable even while the daemon itself is stopped or
- // crash-looping, which `call()` above is not.
+ // crash-looping, which `op()` above is not.
service: {
status: () => ipcRenderer.invoke('node:service-status'),
stop: () => ipcRenderer.invoke('node:service-stop'),